ÃÀ¹úijERPÈí¼þÌṩÉÌÅäÖôíÎóй¶50ÍòÓ¡¶ÈÓû§Êý¾Ý
Ðû²¼Ê±¼ä 2023-01-04
¾ÝýÌå1ÔÂ3ÈÕ±¨µÀ£¬Ñо¿ÈËԱɨÃèµ½ÃÀ¹ú¼ÓÀû¸£ÄáÑÇÖÝijÆóÒµ×ÊÔ´¹æ»®(ERP)Èí¼þÌṩÉÌÅäÖôíÎóµÄElasticsearch·þÎñÆ÷¡£Ð¹Â¶Êý¾ÝÉæ¼°50¶àÍòÓ¡¶ÈÇóÖ°Õß¡¢¸Ã¹«Ë¾Ô±¹¤ÒÔ¼°¸Ã¹«Ë¾µÄ¿Í»§£¬°üÂÞÆ»¹ûºÍÈýÐǵȡ£·ÖÎöÏÔʾ£¬ÆäÖаüÂÞÁè¼Ý575000È˵ÄÊý¾Ý£¬¾ÞϸÁè¼Ý6.3GB£¬¶øÇÒÿÌ춼ÔÚÔö¼ÓеÄÊý¾Ý¡£Ñо¿ÈËÔ±²¢Î´¹ûÈ»¸Ã¹«Ë¾µÄÃû³Æ£¬ÒòΪ·þÎñÆ÷Ä¿Ç°ÈÔÈ»¿ÉÒÔ¹ûÈ»·ÃÎÊ¡£
https://www.hackread.com/erp-firm-expose-india-job-seekers-data/
2¡¢SynologyÐÞ¸´VPN Plus ServerÖЩ¶´CVE-2022-43931
¾Ý1ÔÂ3ÈÕ±¨µÀ³Æ£¬NASÖÆÔìÉÌSynologyÐÞ¸´ÁËÓ°ÏìÆäÅäÖÃΪVPN·þÎñÆ÷ÔËÐеÄ·ÓÉÆ÷ÖеÄÔ½½çдÈ멶´£¨CVE-2022-43931£©¡£¸Ã©¶´´æÔÚÓÚ1.4.3-0534ºÍ1.4.4-0635֮ǰµÄSynology VPN Plus ServerµÄÔ¶³Ì×ÀÃ湦ЧÖУ¬¹¥»÷Õß¿ÉÒÔÀûÓø鶴ִÐÐÈÎÒâÃüÁ©¶´µÄCVSSÆÀ·ÖΪ10£¬¿ÉÔÚµÍÅÓ´óÐÔ¹¥»÷Öб»ÀûÓ㬶øÎÞÐèÄ¿±ê·ÓÉÆ÷µÄȨÏÞ»òÓû§µÄ½»»¥¡£VPN Plus ServerÔÊÐí¹ÜÀíÔ±½«Synology·ÓÉÆ÷ÉèÖÃΪVPN·þÎñÆ÷£¬À´Ô¶³Ì·ÃÎÊ×ÊÔ´¡£´Ë´Î¸üл¹ÐÞ¸´ÁËSRMÖеĶà¸ö©¶´¡£
https://www.bleepingcomputer.com/news/security/synology-fixes-maximum-severity-vulnerability-in-vpn-routers/
3¡¢LockBitΪ¼ÓÄôó¶ù¿ÆÒ½ÔºSickKidsÐû²¼Ãâ·ÑµÄ½âÃÜÆ÷
ýÌå1ÔÂ1Èճƣ¬ÀÕË÷ÍÅ»ïLockBitΪÕë¶Ô¼ÓÄôó¶ù¿ÆÒ½ÔºSickKidsµÄ¹¥»÷ÖÂǸ£¬²¢Ðû²¼Ãâ·ÑµÄ½âÃÜÆ÷¡£¸ÃÍÅ»ïÌåÏÖ£¬ËüµÄÒ»¸öºÏ×÷»ï°éÎ¥·´Á˽ûÖ¹¶Ô¿ÉÄܵ¼Ö¸öÈËËÀÍöµÄ×é֯ϵͳ½øÐмÓÃܵĹæÔò£¬Ä¿Ç°Òѱ»·âËø¡£SickKidsÔÚ2022Äê12ÔÂ18ÈÕÔâµ½¹¥»÷ £¬Æäϵͳ¡¢µç»°Ïß·ºÍÍøÕ¾Êܵ½Ó°Ïì¡£LockBitÌṩµÄÊÇLinux/VMware ESXi½âÃÜÆ÷£¬ÓÉÓÚûÓÐÌرðµÄWindows½âÃÜÆ÷£¬Õâ±íÃ÷¹¥»÷ÕßÖ»ÄܶÔÒ½ÔºÍøÂçÉϵÄÐéÄâ»ú½øÐмÓÃÜ¡£
https://securityaffairs.com/140193/cyber-crime/lockbit-apologized-attack-sickkids.html
4¡¢ÂíÀ´Î÷ÑǵçÐųÆÁè¼Ý25ÍòUnifi Mobile¿Í»§µÄÊý¾Ýй¶
2022Äê12ÔÂ30ÈÕ±¨µÀ£¬ÂíÀ´Î÷ÑǵçÐÅ£¨Telekom Malaysia Bhd£©Í¸Â¶£¬12ÔÂ28ÈÕÓÐ250248¸öUnifi Mobile¿Í»§Êܵ½Êý¾Ý鶵ÄÓ°Ïì¡£ÆäÖмȰüÂÞUnifi MobileµÄ¸öÈË¿Í»§£¬Ò²°üÂÞÖÐСÐÍÆóÒµ(SME)¡£Ð¹Â¶µÄÊý¾ÝÀàÐÍÖ÷ÒªÉæ¼°ÐÕÃû¡¢µç»°ºÅÂëºÍµç×ÓÓʼþ£¬Ã»ÓÐÆäËüÐÅϢй¶¡£TMÌåÏÖÒÑ֪ͨÊÜÓ°ÏìÓû§£¬²¢ÏòÓйØÕþ¸®³ÂËß´ËÊ¡£¸Ã¹«Ë¾²¢Î´ËµÃ÷ÕâÊǺÎÖÖÎ¥¹æÐÐΪ»òÊÇÈçºÎ·¢Éú¡£
https://www.nst.com.my/business/2022/12/865784/250248-unifi-mobile-customers-affected-data-breach-says-tm
5¡¢EmisoftÐû²¼2022ÄêÃÀ¹úÀÕË÷¹¥»÷̬ÊƵÄͳ¼Æ·ÖÎö³ÂËß
1ÔÂ2ÈÕ£¬EmisoftÐû²¼Á˹ØÓÚ2022ÄêÃÀ¹úÀÕË÷¹¥»÷̬ÊƵÄͳ¼Æ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬2022ÄêµÄÀÕË÷¹¥»÷Ó°ÏìÁËÃÀ¹úÕþ¸®¡¢½ÌÓýºÍÒ½ÁÆ´¹Ö±ÁìÓò¹«¹²²¿ÃŵÄ200¶à¸ö´óÐÍ×éÖ¯¡£Óë2021ÄêÏà±È£¬Õë¶ÔµØ·½Õþ¸®µÄÀÕË÷¹¥»÷´Ó77ÆðÔö¼Óµ½105Æð£»ÀÕË÷Èí¼þѬȾÁËÃÀ¹ú89¼Ò½ÌÓý»ú¹¹¡¢44Ëù´óѧºÍ45¸öѧÇø£¬ºÚ¿ÍÔÚÖÁÉÙ58´Î¹¥»÷ÖÐÇÔÈ¡ÁËÊý¾Ý£»Õë¶ÔÒ½ÔººÍ¶àÒ½ÔºÎÀÉúϵͳµÄ¹¥»÷2022ÄêÔö¼Óµ½24Æ𣬿ÉÄÜÓ°Ïì¶à´ï289¼ÒÒ½Ôº¡£
https://www.emsisoft.com/en/blog/43258/the-state-of-ransomware-in-the-us-report-and-statistics-2022/
6¡¢ImpervaÐû²¼2022ÄêDDoS¹¥»÷Íþв̬ÊƵķÖÎö³ÂËß¡£
ImpervaÔÚ2022Äê12ÔÂ27ÈÕÐû²¼ÁË2022ÄêDDoS¹¥»÷Íþв̬ÊƵķÖÎö³ÂËß¡£×Ô2021ÄêÒÔÀ´£¬DDoS¹¥»÷ÔÚÊýÁ¿ºÍƵÂÊÉ϶¼ÓÐÉÏÉýµÄÇ÷ÊÆ£¬Ã¿ÃëÖÁÉÙ50ÍòRPSµÄµÚ7²ãDDoS¹¥»÷ÔÚ¹ýÈ¥Ò»ÄêÖÐÔö¼ÓÁË81%¡£³ýÁËƵÂʸü¸ßÖ®Í⣬2022Äê×î´ó¹¥»÷±È2021ÄêµÄ´ó4.5±¶¡£2021ÄêÏ°ëÄ꣬ƽ¾ùÿÔ·¢Éú2.2´Î´ó¹æÄ£DDoS¹¥»÷£¬2022Äêƽ¾ùÿÔ·¢Éú4´Î´ó¹æÄ£¹¥»÷¡£2021ÄêµÄËùÓй¥»÷¾ùµÍÓÚ100ÍòRPS£¬µ«2022Äê´ó¹æÄ£DDoS¹¥»÷µÄƽ¾ùֵΪ145ÍòRPS£¬ÆäÖÐ×î´ó¹¥»÷µ½´ï1000ÍòRPS¡£2021Ä꣬´ó¹æÄ£¹¥»÷Ö÷ÒªÕë¶ÔÕþ¸®¡¢½ðÈÚºÍÆû³µÍøÕ¾£¬2022ÄêÔòÊÇÕë¶ÔÆû³µ¡¢¼ÆËãºÍµçÐÅÁìÓò¡£
https://www.imperva.com/blog/81-increase-in-large-volume-ddos-attacks/